By NHI Mgmt Group Editorial TeamDomain: AI SecuritySource: AnomaliPublished August 18, 2025

TL;DR: AI can already speed up SOC workflows through copilots, natural-language querying, and higher-fidelity alerting, but panelists cited by Anomali said those gains depend on modern, cloud-native infrastructure and data structures that legacy SOAR stacks cannot provide. The real shift is from analyst task execution to judgment, questioning, and agentic AI oversight.


At a glance

What this is: This is an Anomali panel discussion arguing that AI value in the SOC depends on modern infrastructure, not marketing claims.

Why it matters: It matters to IAM and security practitioners because agentic AI, analyst copilots, and automated workflows all depend on trustworthy data, controlled access, and clear governance over who and what can act.

By the numbers:

  • Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.

👉 Read Anomali's analysis of AI-ready SOC infrastructure and analyst roles


Context

AI in the SOC is not failing because the models are weak. It fails when teams try to layer automation over outdated platforms, rigid playbooks, and poor data structures that cannot support real-time decision-making. The primary problem is governance as much as technology: if systems cannot expose the right context at the right speed, AI can only amplify existing operational limits.

The article is really about the boundary between useful AI augmentation and unsupported AI ambition. That boundary matters for identity programmes because the same access, delegation, and trust questions that shape human and machine operations also govern AI assistants and emerging agentic systems. When AI starts performing work on behalf of analysts, identity, privilege, and auditability stop being background controls and become the operating model.


Key questions

Q: How should security teams govern AI-assisted actions in the SOC?

A: Security teams should treat AI-assisted SOC actions as policy-governed machine behavior, not informal automation. Define which tools the system may access, which actions require approval, and what must be logged for later review. The goal is to keep investigation speed while preserving human accountability and least privilege across prompts, queries, and remediation steps.

Q: Why do legacy SOC platforms limit the value of AI copilots and agents?

A: Legacy platforms often fragment data, slow retrieval, and hard-code response paths, which prevents AI from making useful decisions in context. The model may be capable, but the surrounding architecture cannot supply the right signal fast enough. AI then becomes a reporting layer instead of a control layer.

Q: What do security teams get wrong about agentic AI security tools?

A: The most common mistake is treating agentic AI security as an extension of an existing category such as NHI, endpoint, or DSPM. That view misses the fact that agents operate across multiple deployment patterns and require both posture controls and runtime response. A narrow tool can be useful, but it is not comprehensive governance.

Q: How can organisations tell whether AI SOC ROI is actually improving?

A: Watch for sustained gains in MTTR, MTTD, alert coverage, and false positive reduction, not just a one-time spike after rollout. Pair those metrics with auditability of the investigation output and with analyst feedback on decision quality. If the numbers improve but trust falls, the model is not healthy.


Technical breakdown

Why AI-ready SOC infrastructure matters for automation

AI copilots and agentic workflows depend on fast, structured, high-quality telemetry. Traditional SOC architectures often separate detection, case management, and response into rigid layers, which slows down retrieval and limits what an AI system can safely infer. In practice, this means the model is not the bottleneck. The bottleneck is whether the underlying platform can provide context, permissions, and action paths in real time. When that infrastructure is absent, AI becomes a summarisation layer rather than an operational control plane.

Practical implication: validate data pipelines, response paths, and permission models before expanding AI-driven SOC use cases.

How copilot capabilities change analyst work

Natural-language querying, report drafting, and alert triage are low-risk entry points because they assist analysts rather than replace them. Their value comes from reducing time spent on repetitive interpretation and allowing teams to focus on higher-value investigation. But these capabilities still depend on tightly scoped access to logs, cases, and threat intelligence. If access is too broad, the copilot can surface sensitive material beyond role need; if too narrow, it cannot answer the question well enough to help.

Practical implication: treat copilot access like any other privileged interface and constrain it by role, data class, and investigation scope.

Agentic AI and the governance gap in identity control

Agentic AI changes the model from answering questions to taking actions on a user's behalf. That introduces a new governance problem because the system now needs defined authority, limits, and audit trails for each delegated step. In identity terms, this looks less like a dashboard and more like a non-human actor with scoped permissions. The key challenge is not whether the agent can act, but how to ensure it only acts within approved boundaries, with traceable accountability and revocation paths.

Practical implication: define identity, privilege, and logging rules for AI agents before allowing them to trigger operational actions.


NHI Mgmt Group analysis

AI-ready infrastructure is now the prerequisite for meaningful security automation. The article shows that AI value in the SOC depends on modern platform architecture, not on attaching models to legacy workflows. Rigid SOAR logic and stale data structures turn AI into a decorative layer, while cloud-native pipelines can support contextual decisions at speed. For practitioners, the lesson is that automation maturity starts with infrastructure readiness.

Agentic AI creates a new identity problem inside the SOC. Once a system can take actions rather than only recommend them, it needs boundaries that resemble NHI governance: explicit scope, revocation, logging, and accountability. This is where identity security intersects directly with AI operations. The field should treat agentic systems as governed non-human actors, not as enhanced scripts.

Analyst roles are shifting from execution to supervision, questioning, and exception handling. The article’s strongest signal is that answer generation is becoming cheaper, while judgment remains scarce. That changes how security teams should design workflows, measure productivity, and assign responsibility. The practical conclusion is that human oversight becomes more valuable as AI moves closer to action.

Detection-response latency is becoming a governance issue, not just a SOC metric. When AI is used to reduce false positives and accelerate triage, the organisation is really trying to compress the time between signal, interpretation, and action. If the data path is slow or fragmented, the benefit disappears. For security leaders, this means response design and access design now have to be planned together.

Legacy automation assumptions no longer hold in AI-assisted operations. Traditional playbooks assume deterministic paths and stable conditions, but AI systems are increasingly dynamic, context-sensitive, and capable of branching decisions. That breaks old control expectations around approval, review, and exception handling. Practitioners should redesign operating models around bounded decision authority rather than static workflow ownership.

What this signals

AI adoption in the SOC will increasingly expose access design problems that were previously hidden inside workflow tooling. As systems become more capable of acting on behalf of humans, the programme has to decide whether identity controls are attached to people only or extended to AI-enabled operational actors as well.

Governed automation boundary: the practical line between safe augmentation and unsafe autonomy will be defined by permissions, logging, and revocation. Teams that already manage NHI-style credential discipline will be better positioned to extend the same discipline to agents and copilots.

The next programme risk is not that AI will replace analysts. It is that unmanaged delegation will create actions that are fast, difficult to explain, and hard to revoke. That is why access governance and response design need to be planned as one control system, not two.


For practitioners

  • Audit AI-readiness across SOC data and workflow layers Map where telemetry is stored, how quickly it can be retrieved, and which response actions are exposed to automation. Prioritise the areas where manual handoffs or rigid playbooks would block real-time decisions.
  • Scope copilot access to least-privilege investigation rights Limit natural-language assistants to the cases, logs, and sources required for each analyst role. Review whether the assistant can see more than the user should be able to see in a normal investigation.
  • Define delegated authority for agentic workflows Assign explicit permissions, audit logging, and revocation rules before allowing AI systems to trigger containment, enrichment, or ticketing actions. Treat the agent as a governed non-human identity with bounded authority.
  • Measure automation by decision quality, not task volume Track false-positive reduction, triage accuracy, and containment quality alongside speed metrics. If automation increases throughput but degrades confidence or traceability, the control model is not working.

Key takeaways

  • AI adds value in security operations only when the underlying platform can support real-time, context-rich decisions.
  • Agentic AI introduces identity and accountability questions that look more like NHI governance than traditional automation.
  • For practitioners, the priority is to govern delegated access and auditability before expanding AI from assistance into action.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERNThe article centers on governance for AI-enabled decision-making in security operations.
OWASP Agentic AI Top 10Agentic AI is explicitly discussed as the next operating model for SOC automation.
NIST CSF 2.0PR.AC-4Access control is central when AI systems query logs and trigger actions.
NIST SP 800-53 Rev 5AC-6Least privilege is the core control for delegated SOC access.

Define accountability, oversight, and policy for AI-assisted SOC actions before expanding autonomy.


Key terms

  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions — including calling APIs, writing code, and orchestrating other agents — with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • AI-ready infrastructure: A technology stack that can supply fast, structured, trusted data to AI systems at operational speed. In the SOC, that means telemetry, case data, and response paths are designed for machine consumption, so AI can work with the data rather than around brittle legacy workflows.
  • Delegated Agent Authority: The permission granted to an AI agent to act on behalf of a human user or another agent, inheriting some or all of their access rights. Delegated authority must be explicitly scoped, time-limited, and auditable.
  • Detection-Response Latency: The elapsed time between identifying a security issue and executing a bounded, auditable fix. In data security programmes, long latency means exposure persists after discovery, which undermines the value of detection and weakens compliance evidence.

What's in the full article

Anomali's full post covers the operational detail this analysis intentionally leaves for the source:

  • How the panel described cloud-native data architecture as the difference between useful AI and marketing claims
  • The specific ways copilot workflows are reducing analyst effort in triage, reporting, and alert interpretation
  • Why traditional SOAR patterns limit AI-driven response, including the constraints created by rigid playbooks
  • How the discussion frames the shift from analyst execution to strategic oversight and prompt-driven investigation

👉 The full Anomali post covers the panel discussion on AI copilots, agentic workflows, and the future of analyst work

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity control to the broader governance problems created by AI-enabled operations.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org